Cmseasy

Cmseasy

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 25.04.2024 17:15:49
  • Zuletzt bearbeitet 14.04.2025 13:47:26

An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 17.04.2024 19:15:08
  • Zuletzt bearbeitet 14.04.2025 13:43:41

CMSeasy 7.7.7.9 is vulnerable to code execution.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 17.04.2024 19:15:08
  • Zuletzt bearbeitet 14.04.2025 13:43:17

CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 22.02.2024 16:15:54
  • Zuletzt bearbeitet 03.04.2025 13:18:40

cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 14.01.2024 23:15:28
  • Zuletzt bearbeitet 21.11.2024 08:46:47

A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/language_admin.php. The manipulation of the argument sid leads to sql in...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 27.06.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 05:08:33

An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 15.06.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:07:40

cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 17.05.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:54

cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 17.05.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:54

cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:53

In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.